# Logstash beats SSL file read problem

**URL:** <https://discuss.elastic.co/t/logstash-beats-ssl-file-read-problem/110283>\
**Category:** Logstash\
**Created:** [December 5, 2017, 8:33am UTC](https://discuss.elastic.co/t/logstash-beats-ssl-file-read-problem/110283 "2017-12-05T08:33:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![bodi4](https://avatars.discourse-cdn.com/v4/letter/b/57b2e6/32.png) [@bodi4](https://discuss.elastic.co/u/bodi4)\
**Post date:** [December 5, 2017, 8:33am UTC](https://discuss.elastic.co/t/logstash-beats-ssl-file-read-problem/110283/1 "2017-12-05T08:33:02Z")

</div>

Hi,  
recently installed Logstash 6.0.  
Migrating pipelines from 5.x version.

I have secured connection Filebeat -\> Logstash

But loading pipeline Logstash cannot read certificates:

[2017-12-05T11:24:58,829][ERROR][logstash.inputs.beats] Invalid setting for beats input plugin:

input {  
beats {  
# This setting must be a path  
# File does not exist or cannot be opened /etc/logstash/certs.d/vmlogstash.crt  
ssl\_certificate =\> "/etc/logstash/certs.d/vmlogstash.crt"  
...  
}  
}  
[2017-12-05T11:24:58,830][ERROR][logstash.inputs.beats] Invalid setting for beats input plugin:

input {  
beats {  
# This setting must be a path  
# File does not exist or cannot be opened /etc/logstash/certs.d/vmlogstash.key  
ssl\_key =\> "/etc/logstash/certs.d/vmlogstash.key"  
...  
}  
}

vmlogstash:/etc/logstash # ll certs.d/  
drw-r----- 2 logstash logstash 4096 Dec 1 16:37 ca  
-rw-r----- 1 logstash logstash 1363 Dec 1 16:30 vmlogstash.crt  
-rw-r----- 1 logstash logstash 1675 Dec 1 16:30 vmlogstash.key

input {  
beats {  
port =\> "5045"  
ssl =\> true  
ssl\_certificate\_authorities =\> ["/etc/logstash/certs.d/ca.crt"]  
ssl\_certificate =\> "/etc/logstash/certs.d/${HOSTNAME}.crt"  
ssl\_key =\> "/etc/logstash/certs.d/${HOSTNAME}.key"  
ssl\_verify\_mode =\> "peer"  
}  
}

What can be the problem?

---

<div class="post-metadata">

**Author:** ![bodi4](https://avatars.discourse-cdn.com/v4/letter/b/57b2e6/32.png) [@bodi4](https://discuss.elastic.co/u/bodi4)\
**Post date:** [December 5, 2017, 9:07am UTC](https://discuss.elastic.co/t/logstash-beats-ssl-file-read-problem/110283/2 "2017-12-05T09:07:45Z")

</div>

Figured out.  
Seems logstash doesn't respect read rights for the group 'logstash'

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 5, 2017, 9:42am UTC](https://discuss.elastic.co/t/logstash-beats-ssl-file-read-problem/110283/3 "2017-12-05T09:42:46Z")

</div>

What are the permissions of /etc/logstash/certs.d? The ca subdirectory has the nonsensical file mode 0640 and if that goes for the certs.d subdirectory too then that would certainly explain what you saw.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 2, 2018, 9:43am UTC](https://discuss.elastic.co/t/logstash-beats-ssl-file-read-problem/110283/4 "2018-01-02T09:43:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
